VULNERABILITY INTELLIGENCE

CVE-2011-4566

CVSS score6.4 MEDIUM
EPSS probability9.83%
CISA KEVNot currently listed
Published2011-11-29
Last modified2026-06-16

Description

Integer overflow in the exif_process_IFD_TAG function in exif.c in the exif extension in PHP 5.4.0beta2 on 32-bit platforms allows remote attackers to read the contents of arbitrary memory locations or cause a denial of service via a crafted offset_val value in an EXIF header in a JPEG file, a diffe... .